Zhipu AI’s ZCode Data Upload Controversy Reaches Resolution with Technical Remediation and User Compensation

The contentious data upload controversy surrounding ZCode, an innovative AI coding tool developed by China’s prominent artificial intelligence firm Zhipu AI, is now moving decisively towards a comprehensive resolution, marking a critical moment for user trust and data privacy in the burgeoning AI development landscape. On Monday, Zhipu AI officially announced the successful completion of ZCode’s technical remediation efforts, confirming the deletion of all cloud data implicated in the incident. This critical deletion has been independently verified by two respected third-party organizations: the China Academy of Information and Communications Technology (CAICT) and NSFOCUS, lending significant credibility to Zhipu’s claims. Furthermore, in an overture to its user base, Zhipu AI unveiled a compensation plan that includes the distribution of free Token credits, aiming to assuage concerns and rebuild confidence among developers.

This significant data security incident, which first came to light through the vigilant developer community on September 18, has unfolded over more than ten days, triggering a series of rapid and substantial changes to the ZCode product. These measures included the immediate release of its source code for public scrutiny and the initiation of extensive third-party security checks. The swift and multi-pronged response by Zhipu AI underscores the critical importance of data governance and transparency in the AI sector, particularly for tools that interact directly with sensitive intellectual property like source code.

The Genesis of the Controversy: A Developer’s Discovery

The roots of the controversy trace back to a seemingly innocuous file cleanup operation performed by a developer known as "ferstar." On September 18, while organizing files on a local computer, ferstar stumbled upon an encrypted file, approximately 313MB in size, residing within ZCode’s local data directory. This discovery immediately raised red flags. Through diligent reverse engineering, ferstar deduced that this file was generated by packaging the user’s entire workspace, a comprehensive snapshot created automatically upon user login.

The contents of this unexpected data package were deeply concerning to the developer community. It was found to contain an array of highly sensitive information, including project source code, a complete history of Git commits, LFS (Large File Storage) file caches, and global development configurations. For any developer or enterprise, the unauthorized or undisclosed uploading of such critical assets represents a profound breach of trust and a significant security vulnerability. The immediate question that resonated across developer forums was: how was this data being uploaded, and under what pretense?

Zhipu’s ZCode deletes data and announces compensation after data upload controversy

Further investigation by the community revealed that in earlier versions of ZCode, this data upload feature was enabled by default. Crucially, the client application did not provide a clear, easily accessible option for users to disable this function. This lack of transparency and user control compounded the problem, as some developers reported that even after attempting to turn off privacy and indexing-related settings, background processes within ZCode could continue their attempts to upload the data package. This inherent lack of user agency over their proprietary code assets sparked widespread alarm.

For individual developers, the issue was a matter of personal privacy and intellectual property. For enterprise developers and the companies they represent, the stakes were considerably higher. The potential exposure of proprietary code assets, trade secrets, and internal development configurations posed an existential threat to competitive advantage and operational security. Following the incident’s public disclosure, numerous companies reportedly took immediate action, suspending their use of ZCode and initiating internal audits to ascertain whether their sensitive code had been compromised or inadvertently exposed. This corporate response highlighted the severe real-world implications of such data governance failures in AI tools.

Zhipu AI’s Swift Response and Remediation Efforts: A Detailed Timeline

Recognizing the gravity of the situation and the rapid erosion of user trust, Zhipu AI initiated a series of urgent and systematic changes to ZCode within a mere 72 hours of the incident’s public revelation. The company’s response unfolded as follows:

  • September 18: Initial Apology and Acknowledgment: On the very day the controversy broke, Zhipu AI issued an immediate apology to its user base. In this initial statement, the company candidly acknowledged that the automatic data upload mechanism had not been adequately disclosed to users when the feature was initially launched. This admission was a critical first step in taking responsibility for the oversight.
  • September 19: Product Update and Feature Removal: Just one day after its apology, Zhipu AI released ZCode version 3.14.0. This update was specifically designed to address the core issue by removing the "Repo Wiki" entry, which was linked to the automatic data collection. More importantly, it eliminated the relevant paths responsible for generating and uploading repository snapshots, effectively disabling the controversial upload functionality.
  • September 21: Open-Sourcing and First Round of Security Checks: Two days later, in a move aimed at enhancing transparency and fostering community trust, Zhipu AI open-sourced ZCode’s entire source code. This allowed developers and security researchers globally to independently scrutinize the application’s inner workings and verify the absence of any malicious or undisclosed data collection practices. Concurrently, Zhipu AI released the preliminary results of its first round of third-party security checks. The company emphatically stated that any affected code data had not been retained on its servers and, critically, had never been used for model training—a key concern for users worried about their proprietary code being ingested into a public AI model.

In its most recent announcement, Zhipu AI provided further granular detail regarding the data remediation. The company confirmed that all data objects stored within the implicated Alibaba Cloud OSS (Object Storage Service) bucket, as well as the bucket itself, had been thoroughly deleted. This comprehensive deletion was not merely an internal claim but was subjected to rigorous verification by independent third-party organizations, the China Academy of Information and Communications Technology and NSFOCUS, ensuring an objective audit of the data removal process.

Ensuring Data Deletion and Future Safeguards

Zhipu’s ZCode deletes data and announces compensation after data upload controversy

The involvement of CAICT and NSFOCUS in verifying data deletion is a significant aspect of Zhipu AI’s remediation strategy. The China Academy of Information and Communications Technology is a scientific research institute directly under the Ministry of Industry and Information Technology of China, playing a crucial role in national information and communication technology development and standards. NSFOCUS is a leading provider of enterprise-level network security solutions. Their independent verification lends substantial weight to Zhipu AI’s claims, providing a crucial layer of assurance to a skeptical developer community and enterprise clients.

Looking ahead, Zhipu AI has committed to a fundamental shift in ZCode’s data handling philosophy. The company explicitly stated that ZCode would adopt a strict “no upload unless initiated by the user” approach. This policy mandates that, henceforth, unless users actively and explicitly initiate an upload, all code, project files, and other sensitive development data will remain strictly on local devices. This represents a paradigm shift from the previous default-on, opaque mechanism to a user-centric, opt-in model, granting developers full control over their intellectual property.

The open-source version of ZCode has also been continually updated, now reaching version 3.14.3. Its source code is publicly hosted on GitHub under the permissive Apache-2.0 license, further demonstrating Zhipu AI’s commitment to transparency and community collaboration. This open-source approach allows for ongoing peer review and independent security audits, which can help prevent similar incidents in the future and foster greater trust within the developer ecosystem.

Compensation and Restoring User Trust

Beyond technical fixes and policy changes, Zhipu AI also announced a comprehensive compensation plan, acknowledging the disruption and concern caused to its user base. This plan is designed to address both paid and free users:

  • For Paid Users: All paid users of ZCode will receive four weekly quota reset cards and four five-hour quota reset cards. Each of these cards will be valid for a period of one month, providing substantial additional usage capacity as a gesture of goodwill and compensation for any perceived service interruption or trust deficit.
  • For All Users (Paid and Free): From September 28 to October 7, ZCode initiated the distribution of 100,000 free Token packages to its entire user base. Each of these generous packages contains an astounding 100 million Tokens, providing ample credit for future use of the AI coding tool’s functionalities. This broad-based compensation aims to acknowledge the widespread impact of the incident and encourage continued engagement with ZCode under its new, more transparent data governance framework.

This dual approach of technical remediation and tangible compensation is a critical strategy for Zhipu AI to regain the trust of its user community, particularly in a competitive market where developer loyalty is paramount.

Zhipu’s ZCode deletes data and announces compensation after data upload controversy

Broader Industry Ramifications: A Wake-Up Call for AI Coding Tools

The ZCode incident transcends a single product or company; it serves as a profound wake-up call and highlights a broader, systemic issue facing the rapidly evolving landscape of AI coding tools. As artificial intelligence becomes increasingly integrated into the intricate fabric of software development workflows, the provenance and handling of users’ code become as fundamentally important as the raw capabilities of the underlying AI models.

The industry is witnessing an explosion of AI-powered assistants, from code completion tools to full-fledged code generation platforms. While these tools promise unprecedented gains in productivity and efficiency, the ZCode controversy starkly illuminates the inherent tension between leveraging powerful AI capabilities and upholding stringent data security and privacy standards. Developers and enterprises are inherently cautious about entrusting their proprietary code—often their most valuable intellectual property—to third-party services, especially when the data handling mechanisms are opaque.

For all providers of AI coding tools, this incident underscores the urgent necessity for crystal-clear distinctions between data uploaded at a user’s explicit request and data transferred automatically in the background. The era of "default-on" data collection, particularly for sensitive information like source code, is rapidly drawing to a close. Furthermore, data collection mechanisms must be characterized by absolute transparency, ensuring that users are fully informed about what data is being collected, why it is being collected, and how it will be used. Crucially, users must be empowered with clear, verifiable, and easily accessible controls over whether their data is uploaded, stored, or processed in any way.

The ZCode incident could potentially catalyze a broader industry shift towards more robust data governance standards and ethical AI practices. Competitors in the AI coding space, such as GitHub Copilot (powered by OpenAI Codex), have also faced scrutiny regarding how they handle user code and whether it contributes to model training. This incident will likely compel all players to review and fortify their own data privacy policies, disclosures, and technical implementations to avoid similar public relations crises and maintain user trust. Regulators worldwide are also increasingly scrutinizing AI development, and incidents like this could expedite the formulation of stricter guidelines for AI tools that process sensitive user data.

The Evolving Landscape of AI and Data Privacy

Zhipu’s ZCode deletes data and announces compensation after data upload controversy

While the immediate ZCode incident may be nearing its complete resolution, the underlying challenges it exposed will remain a long-term issue for the industry. As AI coding tools become more deeply embedded in enterprise development environments, the delicate balance between maximizing AI capabilities, boosting developer productivity, and ensuring impregnable code security and data privacy will continue to be a paramount concern.

Future innovations in AI coding will undoubtedly demand even more sophisticated approaches to data handling, privacy-preserving AI techniques (such as federated learning or differential privacy), and robust legal and ethical frameworks. The developer community, increasingly aware of the value and sensitivity of their code, will demand greater accountability and transparency from AI tool providers. The ZCode saga serves as a potent reminder that in the age of AI, trust is the ultimate currency, and transparency in data handling is its most vital component. The industry must learn from this experience, evolving towards a future where the power of AI can be harnessed without compromising the fundamental principles of user control and data integrity.

Related Posts

How Drones and Robots Are Reshaping Renewable-Energy Operations

The traditional landscape of renewable energy operations and maintenance (O&M), particularly for vast solar farms and towering wind turbines, has long been characterized by arduous, time-consuming, and often hazardous manual…

SenseTime Launches SenseMart OS to Bring Embodied Intelligence Into Retail

On September 23, 2026, SenseTime, a global leader in artificial intelligence software, unveiled its groundbreaking SenseMart OS at its Shanghai headquarters, positioning it as a revolutionary physical operating system engineered…

You Missed

Zhipu AI’s ZCode Data Upload Controversy Reaches Resolution with Technical Remediation and User Compensation

Zhipu AI’s ZCode Data Upload Controversy Reaches Resolution with Technical Remediation and User Compensation

Business Committee Urges Taiwan Government to Reform Tax Policies and Remove Vehicle Tariffs to Bolster International Competitiveness

Business Committee Urges Taiwan Government to Reform Tax Policies and Remove Vehicle Tariffs to Bolster International Competitiveness

China Advances Comprehensive Legal Framework with New Draft Law on Countering Cyberviolence

China Advances Comprehensive Legal Framework with New Draft Law on Countering Cyberviolence

China’s Coal Power Share Dips Below 50% for the First Time as Renewables Gain Momentum

China’s Coal Power Share Dips Below 50% for the First Time as Renewables Gain Momentum

Hong Kong Faces Intensified Crackdown as Activists and Journalists Targeted in September

Hong Kong Faces Intensified Crackdown as Activists and Journalists Targeted in September

Chinese Architect Ma Yansong Unveils Visionary Lucas Museum, Blending Sci-Fi Aesthetics with Ancient Nature Philosophy

  • By Nana Wu
  • October 5, 2026
  • 2 views
Chinese Architect Ma Yansong Unveils Visionary Lucas Museum, Blending Sci-Fi Aesthetics with Ancient Nature Philosophy